mruby records
42 published records for vendor mruby.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-476 NULL Pointer Dereference10
- CWE-416 Use After Free8
- CWE-125 Out-of-bounds Read7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-122 Heap-based Buffer Overflow4
- CWE-190 Integer Overflow or Wraparound2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
42 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-10191No exploit | In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presemruby · mruby · CWE-190 | Critical9.8 | — | 2.6% | Apr 17, 2018 |
40Plan | CVE-2018-10199No exploit | In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy().mruby · mruby · CWE-416 | Critical9.8 | — | 2.3% | Apr 18, 2018 |
40Plan | CVE-2018-11743No exploit | The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attackers to cause a deniamruby · mruby · CWE-824 | Critical9.8 | — | 2.2% | Jun 5, 2018 |
40Plan | CVE-2020-15866No exploit | mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling.mruby · mruby · CWE-787 | Critical9.8 | — | 2.1% | Jul 21, 2020 |
40Plan | CVE-2022-1212No exploit | Use-After-Free in str_escape in mruby/mruby in mruby/mrubymruby · mruby · CWE-416 | Critical9.8 | — | 1.8% | Apr 5, 2022 |
39Monitor | CVE-2022-1276No exploit | Out-of-bounds Read in mrb_get_args in mruby/mrubymruby · mruby · CWE-125 | Critical9.8 | — | 1.6% | Apr 10, 2022 |
39Monitor | CVE-2020-6840No exploit | In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.mruby · mruby · CWE-416 | Critical9.8 | — | 1.5% | Jan 10, 2020 |
39Monitor | CVE-2020-6838No exploit | In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c.mruby · mruby · CWE-416 | Critical9.8 | — | 1.5% | Jan 10, 2020 |
39Monitor | CVE-2022-0080No exploit | Heap-based Buffer Overflow in mruby/mrubymruby · mruby · CWE-122 | Critical9.8 | — | 1.4% | Jan 2, 2022 |
39Monitor | CVE-2020-6839No exploit | In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c.mruby · mruby · CWE-787 | Critical9.8 | — | 1.4% | Jan 10, 2020 |
39Monitor | CVE-2022-0570No exploit | Heap-based Buffer Overflow in mruby/mrubymruby · mruby · CWE-122 | Critical9.8 | — | 1.2% | Feb 14, 2022 |
39Monitor | CVE-2022-1286No exploit | heap-buffer-overflow in mrb_vm_exec in mruby/mruby in mruby/mrubymruby · mruby · CWE-122 | Critical9.8 | — | 1.2% | Apr 10, 2022 |
39Monitor | CVE-2022-0631No exploit | Heap-based Buffer Overflow in mruby/mrubymruby · mruby · CWE-122 | Critical9.8 | — | 0.9% | Feb 18, 2022 |
36Monitor | CVE-2022-0623No exploit | Out-of-bounds Read in mruby/mrubymruby · mruby · CWE-125 | Critical9.1 | — | 1.6% | Feb 17, 2022 |
36Monitor | CVE-2022-0525No exploit | Out-of-bounds Read in mruby/mrubymruby · mruby · CWE-125 | Critical9.1 | — | 1.2% | Feb 9, 2022 |
36Monitor | CVE-2022-1106No exploit | use after free in mrb_vm_exec in mruby/mrubymruby · mruby · CWE-416 | Critical9.1 | — | 1.0% | Mar 27, 2022 |
36Monitor | CVE-2022-0717No exploit | Out-of-bounds Read in mruby/mrubymruby · mruby · CWE-125 | Critical9.1 | — | 0.9% | Feb 22, 2022 |
32Monitor | CVE-2022-1071No exploit | User after free in mrb_vm_exec in mruby/mrubymruby · mruby · CWE-416 | High8.2 | — | 0.9% | Mar 26, 2022 |
31Monitor | CVE-2018-12249No exploit | An issue was discovered in mruby 1.4.1.mruby · mruby · CWE-476 | High7.5 | — | 2.1% | Jun 12, 2018 |
31Monitor | CVE-2020-36401No exploit | mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).mruby · mruby · CWE-415 | High7.8 | — | 1.0% | Jun 30, 2021 |
31Monitor | CVE-2017-9527No exploit | The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and mruby · mruby · CWE-416 | High7.8 | — | 1.0% | Jun 11, 2017 |
31Monitor | CVE-2022-1427No exploit | Out-of-bounds Read in mrb_obj_is_kind_of in in mruby/mrubymruby · mruby · CWE-125 | High7.8 | — | 0.5% | Apr 22, 2022 |
31Monitor | CVE-2022-1934No exploit | Use After Free in mruby/mrubymruby · mruby · CWE-416 | High7.8 | — | 0.4% | May 30, 2022 |
30Monitor | CVE-2021-4110No exploit | NULL Pointer Dereference in mruby/mrubymruby · mruby · CWE-476 | High7.5 | — | 1.6% | Dec 15, 2021 |
30Monitor | CVE-2018-12247No exploit | An issue was discovered in mruby 1.4.1.mruby · mruby · CWE-476 | High7.5 | — | 1.6% | Jun 12, 2018 |
- CVE-2018-1019140Plan
In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the prese
CriticalCVSS 9.8No exploitEPSS 3%mruby · mrubyApr 17, 2018
- CVE-2018-1019940Plan
In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy().
CriticalCVSS 9.8No exploitEPSS 2%mruby · mrubyApr 18, 2018
- CVE-2018-1174340Plan
The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attackers to cause a denia
CriticalCVSS 9.8No exploitEPSS 2%mruby · mrubyJun 5, 2018
- CVE-2020-1586640Plan
mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling.
CriticalCVSS 9.8No exploitEPSS 2%mruby · mrubyJul 21, 2020
- CVE-2022-121240Plan
Use-After-Free in str_escape in mruby/mruby in mruby/mruby
CriticalCVSS 9.8No exploitEPSS 2%mruby · mrubyApr 5, 2022
- CVE-2022-127639Monitor
Out-of-bounds Read in mrb_get_args in mruby/mruby
CriticalCVSS 9.8No exploitEPSS 2%mruby · mrubyApr 10, 2022
- CVE-2020-684039Monitor
In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.
CriticalCVSS 9.8No exploitEPSS 2%mruby · mrubyJan 10, 2020
- CVE-2020-683839Monitor
In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c.
CriticalCVSS 9.8No exploitEPSS 2%mruby · mrubyJan 10, 2020
- CVE-2022-008039Monitor
Heap-based Buffer Overflow in mruby/mruby
CriticalCVSS 9.8No exploitEPSS 1%mruby · mrubyJan 2, 2022
- CVE-2020-683939Monitor
In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c.
CriticalCVSS 9.8No exploitEPSS 1%mruby · mrubyJan 10, 2020
- CVE-2022-057039Monitor
Heap-based Buffer Overflow in mruby/mruby
CriticalCVSS 9.8No exploitEPSS 1%mruby · mrubyFeb 14, 2022
- CVE-2022-128639Monitor
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in mruby/mruby
CriticalCVSS 9.8No exploitEPSS 1%mruby · mrubyApr 10, 2022
- CVE-2022-063139Monitor
Heap-based Buffer Overflow in mruby/mruby
CriticalCVSS 9.8No exploitEPSS 1%mruby · mrubyFeb 18, 2022
- CVE-2022-062336Monitor
Out-of-bounds Read in mruby/mruby
CriticalCVSS 9.1No exploitEPSS 2%mruby · mrubyFeb 17, 2022
- CVE-2022-052536Monitor
Out-of-bounds Read in mruby/mruby
CriticalCVSS 9.1No exploitEPSS 1%mruby · mrubyFeb 9, 2022
- CVE-2022-110636Monitor
use after free in mrb_vm_exec in mruby/mruby
CriticalCVSS 9.1No exploitEPSS 1%mruby · mrubyMar 27, 2022
- CVE-2022-071736Monitor
Out-of-bounds Read in mruby/mruby
CriticalCVSS 9.1No exploitEPSS 1%mruby · mrubyFeb 22, 2022
- CVE-2022-107132Monitor
User after free in mrb_vm_exec in mruby/mruby
HighCVSS 8.2No exploitEPSS 1%mruby · mrubyMar 26, 2022
- CVE-2018-1224931Monitor
An issue was discovered in mruby 1.4.1.
HighCVSS 7.5No exploitEPSS 2%mruby · mrubyJun 12, 2018
- CVE-2020-3640131Monitor
mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).
HighCVSS 7.8No exploitEPSS 1%mruby · mrubyJun 30, 2021
- CVE-2017-952731Monitor
The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and
HighCVSS 7.8No exploitEPSS 1%mruby · mrubyJun 11, 2017
- CVE-2022-142731Monitor
Out-of-bounds Read in mrb_obj_is_kind_of in in mruby/mruby
HighCVSS 7.8No exploitEPSS 0%mruby · mrubyApr 22, 2022
- CVE-2022-193431Monitor
Use After Free in mruby/mruby
HighCVSS 7.8No exploitEPSS 0%mruby · mrubyMay 30, 2022
- CVE-2021-411030Monitor
NULL Pointer Dereference in mruby/mruby
HighCVSS 7.5No exploitEPSS 2%mruby · mrubyDec 15, 2021
- CVE-2018-1224730Monitor
An issue was discovered in mruby 1.4.1.
HighCVSS 7.5No exploitEPSS 2%mruby · mrubyJun 12, 2018